PDF creation script is vulnerable to Cross-Site Scripting (or "Code Injection") issues through which an attacker can inject arbitrary HTML code. For example during an invoice creation, an attacker can use its information written on the invoice to insert a malicious "link" tag pointing to a local phar archive and trigger a PHP Object Injection through the phar:// scheme once the web application reads that file. References: https://seclists.org/fulldisclosure/2019/Mar/36
Created php-tcpdf tracking bugs for this issue: Affects: epel-all [bug 1695301] Affects: fedora-all [bug 1695300]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.